What Happened? 

In June 2026, Amazon One Medical disclosed a security incident after an unauthorised party gained access to a third-party file storage system containing archived patient records. 

The affected system held legacy data inherited through One Medical’s acquisition of Iora Health (now One Medical Seniors), rather than information from its current electronic medical record platform. While the number of affected individuals has not been confirmed publicly, the cyber extortion group ShinyHunters claimed to have stolen 8.8TB of archived patient data and threatened to publish it unless ransom demands were met. 

According to One Medical, the unauthorised access took place between the 8th and 11th June and was discovered on the 13th June. The company said its current clinics, services, electronic medical record system and wider Amazon Health Services infrastructure were not affected. 

Although investigations are ongoing and ShinyHunters’ claims have not been independently verified, the incident highlights a growing challenge facing healthcare organisations. Patient data remains one of the most valuable assets cyber criminals can steal, and legacy systems continue to introduce risk long after an acquisition has been completed. 

The incident also demonstrates that even organisations backed by some of the world’s largest technology companies aren’t immune from cyber attacks. 

Why Healthcare Data Is Such a Valuable Target 

Healthcare organisations are responsible for some of the most sensitive information people will ever share. Medical histories, diagnoses, prescriptions, insurance details and identification information all have significant value to cyber criminals, as stolen healthcare records can be used to commit identity fraud, support highly targeted phishing attacks, or be sold on criminal marketplaces alongside other personal information.  

For organisations, the consequences of losing that information extend far beyond the initial breach. Patients place enormous trust in healthcare providers to protect deeply personal records, so any compromise can damage confidence, attract regulatory scrutiny, and have lasting reputational consequences. 

Healthcare providers also operate in environments where information needs to be available quickly. Doctors, nurses and clinical staff rely on immediate access to patient records to deliver care, often across multiple locations and systems. Balancing accessibility with strong security controls is essential, but it also creates challenges that attackers are keen to exploit. 

The One Medical breach reinforces why healthcare continues to be a prime target. Whether attackers are targeting live systems or archived patient records, they know the information they’ll find is valuable and highly sensitive, making healthcare organisations an attractive target. 

Legacy Systems Can Create Lasting Security Risks 

One of the most interesting aspects of this incident is that attackers didn’t gain access to One Medical’s live healthcare systems. Instead, the breach involved archived patient records stored on a legacy third-party platform that had been inherited through previous acquisitions. 

This highlights a challenge many organisations face after mergers and acquisitions. While businesses often focus on integrating people, processes and technology, older systems and archived data can stay in place for years, increasing an organisation’s attack surface. 

From a security perspective, inherited systems don’t become any less important just because they’re no longer used every day. They may still contain large volumes of sensitive information, and organisations are responsible for protecting that data regardless of when or how it was acquired. 

For healthcare providers, patient records often need to be kept for many years, and the responsibility for protecting that information doesn’t disappear just because it’s stored in an older system. Legacy environments need the same care and attention as the systems employees use every day. 

What One Medical Did Well 

No organisation wants to experience a data breach, but how an organisation responds can make a significant difference. 

After identifying the unauthorised access, One Medical moved quickly to secure the affected storage environment, revoke user access, rotate credentials for users of the system, and begin a forensic investigation into what had happened. 

The organisation also communicated clearly about the scope of the incident, explaining that the breach was limited to a legacy archive and confirming that its current electronic medical record system, clinics and healthcare services had not been affected. 

Being open about what happened is just as important as responding quickly. When a security incident affects sensitive information, patients want honest answers about what happened, what information may have been involved, and what the organisation is doing to protect them going forward. 

While no organisation can completely eliminate cyber risk, responding quickly, containing the incident and communicating openly are all characteristics of a mature security programme. 

What Organisations Can Learn 

The One Medical breach is a reminder that cyber security doesn’t end with the systems employees use every day. Older platforms can still hold huge amounts of sensitive information, particularly after mergers and acquisitions, making them just as attractive to attackers as live production environments. 

That’s why organisations need a clear understanding of where sensitive information is stored and who can access it. Legacy systems shouldn’t be forgotten just because they’re no longer part of day-to-day operations. If archived data still needs to be retained, it deserves the same level of protection as any current system, with access limited to employees who genuinely need it. 

Monitoring for unusual activity also plays an important role. Spotting unexpected access to archived data or legacy environments early can give security teams the opportunity to investigate before a small issue develops into a much larger incident. 

Technology, however, can only do so much on its own. Employees also need to understand why healthcare data is so valuable and how attackers try to obtain it. When people appreciate the sensitivity of the information they work with, they’re more likely to question unusual requests, follow security procedures and report anything that doesn’t seem right. 

Helping employees build that understanding is a key part of reducing human cyber risk. When people know what to look out for and feel confident responding to suspicious activity, they become another layer of protection for the organisation. 

Help Employees Protect Your Most Sensitive Information 

Technology can help secure your systems, but your people still make countless decisions every day that influence cyber risk. 

MetaCompliance helps organisations reduce human cyber risk through engaging security awareness trainingphishing simulations, and policy management solutions that build secure behaviours across the workforce. 

Whether your organisation works in healthcare, finance, education, or any other sector handling sensitive information, we can help employees recognise threats, make better security decisions, and become an active line of defence against cyber attacks. 

Get in touch to find out how MetaCompliance can help strengthen your organisation’s cyber resilience. 

FAQs

Why do cyber criminals target healthcare organisations?

Healthcare providers hold highly valuable personal information, including medical records, identity data, insurance details, and contact information. This data can all be exploited by cybercriminals for fraud, identity theft, phishing, and other criminal activity.